{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cicd/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-63077"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TeamCity On-Premises"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","cicd","jetbrains"],"_cs_type":"threat","_cs_vendors":["JetBrains"],"content_html":"\u003cp\u003eOn July 27, 2026, JetBrains disclosed CVE-2026-63077, a critical deserialization vulnerability affecting all versions of TeamCity On-Premises. With a CVSS score of 9.8, the vulnerability allows an unauthenticated remote attacker to interact with the server's agent polling protocol to bypass authentication mechanisms. By sending specifically crafted payloads, an attacker can achieve remote code execution (RCE) with the privileges of the underlying TeamCity server process.\u003c/p\u003e\n\u003cp\u003eThis vulnerability presents a severe risk to CI/CD environments, as successful exploitation enables attackers to harvest stored credentials, manipulate build artifacts, and gain persistent access to the broader development infrastructure. While JetBrains reported no evidence of active exploitation at the time of disclosure, the simplicity of the attack vector makes patching or applying the provided security plugin an immediate requirement for all on-premises deployments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing TeamCity instances.\u003c/li\u003e\n\u003cli\u003eAttacker establishes a connection to the TeamCity server using the agent polling protocol.\u003c/li\u003e\n\u003cli\u003eAttacker sends a malicious, serialized payload to the targeted endpoint.\u003c/li\u003e\n\u003cli\u003eThe TeamCity server deserializes the untrusted data without sufficient validation.\u003c/li\u003e\n\u003cli\u003eThe deserialization process triggers execution of arbitrary code within the context of the server process.\u003c/li\u003e\n\u003cli\u003eAttacker gains initial access and executes OS commands to dump credentials or deploy further malicious payloads.\u003c/li\u003e\n\u003cli\u003eAttacker uses compromised credentials to move laterally into the CI/CD pipeline.\u003c/li\u003e\n\u003cli\u003eAttacker compromises build processes or exfiltrates proprietary source code from the build environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full system compromise of the TeamCity server, enabling attackers to read sensitive build configurations, steal hardcoded credentials, and inject malicious code into CI/CD pipelines. This could lead to a wide-scale supply chain attack, impacting software integrity for downstream users of the organization's products.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching or applying workarounds to mitigate CVE-2026-63077:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade TeamCity On-Premises to version 2025.11.7 or 2026.1.3 immediately.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not feasible, apply the JetBrains security patch plugin for all versions 2017.1 and later.\u003c/li\u003e\n\u003cli\u003eRestrict network access to TeamCity servers via firewall rules to ensure only authorized agent IPs and management workstations have ingress access to the polling protocol.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T16:47:46Z","date_published":"2026-07-29T16:47:46Z","id":"https://feed.craftedsignal.io/briefs/2026-07-jetbrains-teamcity-rce/","summary":"A critical insecure deserialization vulnerability (CVE-2026-63077) in JetBrains TeamCity allows unauthenticated remote attackers to execute arbitrary system commands via the agent polling protocol.","title":"Critical Unauthenticated RCE in JetBrains TeamCity","url":"https://feed.craftedsignal.io/briefs/2026-07-jetbrains-teamcity-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cicd","version":"https://jsonfeed.org/version/1.1"}